Identity and the gate
The pen drive is the identity. There is no login and no account screen. An encrypted Ed25519 key file on a removable drive, whose private half only decrypts under this machine's device fingerprint, is what unlocks Lens. Drives over 128 GB or Time Machine destinations are refused as keys with no override: a key is a stick small enough to leave with its owner. Multiple keys can live on one machine; a session pins to its key and other keys' servers are never listed.
Two factors at the door, key first. The gate order is KEY, then Touch ID. With no key plugged Lens shows the "Welcome to Lens" door with "I have a key" and "Start a new account" — it never assumes a new account. Touch ID falls back to the account password on a Mac with no sensor or a closed lid, and to key-only where nothing can be evaluated; the degraded state is always said on screen. The Windows build has no biometric step.
Product activation key (LFL1.). A new account opens with the activation key from lockflare.com/create-account, opened on this computer with the envelope key built into Lens and LockFlare's Ed25519 signature checked locally — nothing is asked of anyone. The key is written onto the drive beside the identity and carries the account: name, email, and how many servers are free.
Server licenses (LFS1.). A server license is issued at lockflare.com for one IP address and carries that address inside it, signed. Adding a Lens server means pasting the key; the address comes out of it, nothing is typed twice. Three checks: at the door (a key issued to another account is refused, so accounts cannot be pooled onto one map), on the box (/var/lib/lens/license is read on every connect and kept right), and at the root door (every root path in the app asks whether this is a licensed server). The shell itself is never refused for a license.
Lens server vs console. Two kinds of server go on the map. A Lens server carries a license and gets everything Lens does to a box as root: Security Setup, System Setup, Backups, the tools, the clusters. A console carries no license and no count: a box Lens is a terminal to — shell, Files, Tunnels, Snippets, History, everything the login can do by hand. Locked features stay on the rail, marked, and say what they are when pressed — never greyed, never silent. A console becomes a Lens server on Edit the day a key for its address is pasted.
Remove permanently / Remove and add another. A licensed server leaves two ways and the license goes with it: REMOVE PERMANENTLY hands its remaining days back to the account as credit; REMOVE AND ADD ANOTHER moves the license and its time to a new address. Both finish on lockflare.com; servers removed with a license still pending are held in the store and counted on the map and in Setup › Licenses so a closed browser loses nothing. Renewal opens 60 days before a key ends.
Recovery bundle. For the worst day (key lost, no backup, computer gone): lockflare.com/recover takes the account's email, password and one of its server addresses, mails a 6-digit code, and hands back a bundle — the account license and every server key as one string. Pasted at the gate, Lens writes a new key with the account inside and every server goes back on the map with its license. Lens sends nothing; the visit is the browser's.
Encrypted backup on the key (.lf-backup.enc). One file on the pen drive holding everything Lens has: the whole map document (servers, groups, boards, snippets, tunnels, grants, templates, diagrams, clusters), the audit ledger, the certificate vault and the saved credentials, decrypted from the credstore at write time and sealed inside. The data key is wrapped twice: under the operator's passphrase (PBKDF2-SHA512 + AES-256-GCM, the recovery path that works on a new machine) and under the drive's deterministic signature (so the automatic rewrite while the key is plugged needs no passphrase). A fresh Lens with a verified key offers the restore at the gate, before anything draws.
Travel copy (.lf-travel-<id>.key). A key is bound to the machine that made it, and a new account elsewhere would be a new key id, invalidating every server license. The travel copy is the same key pair, id and account license sealed under a passphrase, written beside the encrypted backup. On a new computer the gate offers "Your key, on a new computer": it enrols the same key id there and, with the backup on the drive, brings the whole map back under the same passphrase. Setup › Your key makes, reseals or removes it, and the trade-off (possession + a secret instead of possession + a machine) is said on screen.
Duplicate my USB drive. A locked, full-screen ceremony that makes a twin key for the drawer or the other bag. The key is read into memory first under Touch ID while the source is plugged, so the screen can say UNPLUG YOUR CURRENT KEY and mean it; the new stick is watched for, written, read back, and only then called ready. Nothing else in Lens can be clicked mid-ceremony and the key-removed overlay stands down because the key being out is the plan.
Key-removed lock. Pulling the drive after unlocking raises an opaque overlay ("Connect your pen drive"): the unlocked state, the shells and every job survive underneath, and reinserting the key puts the operator back exactly where they were. A lock, not a logout. The overlay is opaque on purpose: what is behind it is exactly what the absent key protects.
Session lock. A button in the title bar blurs the console past reading and asks for the second factor to come back. The key stays in, shells stay open, jobs carry on; keystrokes are swallowed at the capture phase so a terminal behind the blur cannot be typed into. Nothing dismisses it but the factor.
Welcome. One branded moment per unlock: what this is, that you are in, and with which physical key. Skippable by any key or click; nothing load-bearing, no "sign in as" language anywhere.
